VDB

CVE-2023-29007

CVE-2023-29007 PUBLISHED CVSS 7.300000190734863 HIGH

A specially crafted `.gitmodules` file with submodule URLs that are longer than 1024 characters can used to exploit a bug in `config.c::git_config_copy_or_rename_section_in_file()`. This bug can be used to inject arbitrary configuration into a user's `$GIT_DIR/config` when attempting to remove the con-figuration section associated with that submodule. When the attacker injects configuration values which specify executables to run (such as `core.pager`, `core.editor`, `core.sshCommand`, etc.) this can lead to a remote code execution.

EPSS 0.62% · 70.3th percentile

Risk Scores

CVSS v3.1
7.300000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
EPSS Score
0.62%
70.3th percentile

Affected Products

VendorProductVersions
ABBABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3
ABBABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3

Timeline

  • Apr 25, 2023 CVE Published
  • Apr 26, 2023 EPSS Score
  • Jul 9, 2023 EPSS Score
  • Sep 22, 2023 EPSS Score
  • Dec 5, 2023 EPSS Score
  • Jan 11, 2024 EPSS Score
  • Feb 8, 2024 PoC Published
  • Mar 26, 2024 EPSS Score
  • Jun 8, 2024 EPSS Score
  • Aug 21, 2024 EPSS Score
  • Nov 4, 2024 EPSS Score
  • Jan 18, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›